WordPress · Realhomes Memberships · CVE-2026-15246
**Name of the Vulnerable Software and Affected Versions**
RealHomes Memberships WordPress plugin versions prior to 3.1.0
**Description**
An issue exists where the plugin fails to verify if a membership payment was completed and does not validate a nonce (a unique token used to prevent cross-site request forgery) or the user's capability before granting a paid membership package. This allows any authenticated user, including those with Subscriber roles, to obtain paid membership packages without payment.
**Recommendations**
Update the plugin to version 3.1.0 or later.